Trezor says attackers breached its email provider and sent phishing messages from a real Trezor address

Trezor says attackers breached its third-party email provider and used that access to send phishing emails to customers from a legitimate Trezor address. The fake messages claimed a made-up STM32 hardware vulnerability could expose wallet recovery seeds and urged users to click through. Trezor says it took the malicious domain offline and is investigating how attackers gained access to its legitimate email-sending setup.
Why it matters: Trezor users face a high-risk phishing threat because the messages appeared to come from a real company address and targeted people who hold cryptocurrency. Customers should avoid links in recent Trezor security emails, verify messages through official channels, and never share wallet seed phrases.

Sources

Trezor warns users of email provider breach, phishing attacks
Sergiu Gatlan 2026.09.10 100% relevant
This article establishes a distinct new incident: a breach of Trezor's third-party email provider that enabled phishing from a legitimate Trezor address, separate from the previously tracked ShipMonk customer-data breach.
← Back to all stories